ÿÖÜÉý¼¶Í¨¸æ-2022-06-14

Ðû²¼Ê±¼ä 2022-06-14

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_GitLab_Ó²±àÂëÎó²î[CVE-2021-22205][CNNVD-202104-1685]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

GitLabÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬£¬ £¬£¬£¬ £¬Ê¹ÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬ £¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£¡£¡£ÔÚGitLabCE/EE°æ±¾14.7(14.7.7֮ǰ)¡¢14.8(14.8.5֮ǰ)ºÍ14.9(14.9.2֮ǰ)ÖÐʹÓÃOmniAuthÌṩÉÌ(ÈçOAuth¡¢LDAP¡¢SAML)×¢²áµÄÕÊ»§ÉèÖÃÁËÓ²±àÂëÃÜÂ룬£¬ £¬£¬£¬ £¬ÔÊÐí¹¥»÷ÕßDZÔڵؿØÖÆÕÊ»§¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai.Putin_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

¼ì²âµ½Mirai.PutinЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øMirai.Putin£¬£¬ £¬£¬£¬ £¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖMirai.Putin¡£¡£¡£Mirai½©Ê¬ÍøÂçÈ䳿Ö÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍø×°±¸£¨IoT£©£¬£¬ £¬£¬£¬ £¬°üÀ¨£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVR×°±¸µÈµÈ£¬£¬ £¬£¬£¬ £¬IoT×°±¸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬£¬ £¬£¬£¬ £¬Òò±£´æÄ¬ÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØÎó²îδʵʱÐÞ¸´µÈÒòËØ£¬£¬ £¬£¬£¬ £¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬ £¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£ÓÉÓÚÔ´´úÂëÒѾ­¹ûÕæ£¬£¬ £¬£¬£¬ £¬Mirai·ºÆðÁËÐí¶à±äÖÖ£¬£¬ £¬£¬£¬ £¬±¾ÊÂÎñÕë¶ÔÆä±äÖÖMirai.Putin¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

¼ì²âµ½MiraiЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øMirai£¬£¬ £¬£¬£¬ £¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai¼«Æä±äÖÖ¡£¡£¡£Mirai½©Ê¬ÍøÂçÈ䳿Ö÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍø×°±¸£¨IoT£©£¬£¬ £¬£¬£¬ £¬°üÀ¨£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVR×°±¸µÈµÈ£¬£¬ £¬£¬£¬ £¬IoT×°±¸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬£¬ £¬£¬£¬ £¬Òò±£´æÄ¬ÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØÎó²îδʵʱÐÞ¸´µÈÒòËØ£¬£¬ £¬£¬£¬ £¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬ £¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¹¤Ç©×ÖÌÃÊý¾Ý·¢Ã÷

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

³ÌÐòδ¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®¾ÙÐмì²â£¬£¬ £¬£¬£¬ £¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¿ØÖÆ·´ÐòÁл¯Àú³Ì£¬£¬ £¬£¬£¬ £¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂ룬£¬ £¬£¬£¬ £¬´Ó¶øµÖ´ï´úÂëÖ´ÐУ¬£¬ £¬£¬£¬ £¬SQL×¢È룬£¬ £¬£¬£¬ £¬Ä¿Â¼±éÀúµÈ²»¿É¿ØÐ§¹û£¬£¬ £¬£¬£¬ £¬Î£º¦½Ï´ó¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_SaltStack_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SaltStackÊÇ»ùÓÚPython¿ª·¢µÄÒ»Ì×C/S¼Ü¹¹ÉèÖÃÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬ £¬ÊÇÒ»¸öЧÀÍÆ÷»ù´¡¼Ü¹¹¼¯Öл¯ÖÎÀíÆ½Ì¨£¬£¬ £¬£¬£¬ £¬¾ß±¸ÉèÖÃÖÎÀí¡¢Ô¶³ÌÖ´ÐС¢¼à¿ØµÈ¹¦Ð§¡£¡£¡£ÔÚCVE-2020-11651ÈÏÖ¤ÈÆ¹ýÎó²îÖУ¬£¬ £¬£¬£¬ £¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬ £¬£¬£¬ £¬¿ÉÒÔÈÆ¹ýSaltMasterµÄÑéÖ¤Âß¼­£¬£¬ £¬£¬£¬ £¬Å²ÓÃÏà¹ØÎ´ÊÚȨº¯Êý¹¦Ð§£¬£¬ £¬£¬£¬ £¬´Ó¶ø¿ÉÒÔÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£Îó²îÓÉClearfuncsÀàÒýÆð,¸ÃÀàÎÞÒâÖÐ̻¶ÁË_send_pub()ºÍ_prep_auth_info()ÒªÁì¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆµÄÇëÇó¿ÉÔÚminion¶ËЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁÄܹ»ÌáÈ¡¸ùÃÜÔ¿À´Å²ÓÃmaster¶ËЧÀÍÆ÷ÉϵÄÖÎÀíÏÂÁî¡£¡£¡£Ó°Ïì°æ±¾SaltStack<2019.2.4SaltStack<3000.2

¸üÐÂʱ¼ä£º

20220614

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_IoT.Moobot_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

¼ì²âµ½MoobotЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øMoobot£¬£¬ £¬£¬£¬ £¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£¡£¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçMoobot¡£¡£¡£MoobotÊÇIoT½©Ê¬ÍøÂçMiraiµÄÖ÷Òª±äÖÖÖ®Ò»£¬£¬ £¬£¬£¬ £¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÌᳫDDoS¹¥»÷£¬£¬ £¬£¬£¬ £¬Í¨¹ýÖÖÖÖÎó²îÈö²¥×ÔÉí¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_JAVA_ŲÓÃRMIÔ¶³ÌÏÂÔØclass

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

´ËÊÂÎñ¼ì²âJAVAŲÓÃRMIÔ¶³ÌÏÂÔØclassµÄÐÐΪ¡£¡£¡£RMI¼´Ô¶³ÌÒªÁìŲÓ㬣¬ £¬£¬£¬ £¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³ÌÀú³ÌŲÓõÄjavaAPI.ÔÚjavaÎó²îÖУ¬£¬ £¬£¬£¬ £¬±£´æ´ó×Ú·´ÐòÁл¯ºÍÏÂÁîÖ´ÐÐÎó²î»áʹÓõ½RMIÔ¶³Ì»á¼û¶ñÒâÀàµÄÊÖ·¨£¬£¬ £¬£¬£¬ £¬À´ÊµÏÖí§ÒâÏÂÁîÖ´ÐУ¬£¬ £¬£¬£¬ £¬Î£º¦½Ï´ó¡£¡£¡£

¸üÐÂʱ¼ä£º

20220614